Method for changing an existing access key in a field device in automation technology
Abstract
A method for changing an existing access key in a field device in automation technology includes the steps of: providing a key database on a database server; generating a key data set for a user authorized to access or a control unit authorized to access from the key database; and transferring the key data set to the control unit of the access-authorized user or the access-authorized control unit, so that the control unit of the access-authorized user or the access-authorized control unit has the existing access keys of the field devices for which an access authorization exists. The key database is for a plurality of field devices and contains at least a field device identifier of a respective field device, the existing access key of the respective field device and the identifier of a user authorized to access and/or a control unit authorized to access the respective field device.
Claims
exact text as granted — not AI-modifiedThe invention claimed is:
1 . A method for changing an existing access key in a field device in automation technology, wherein a field device identifier and the existing access key are stored in the field device, wherein a control unit can be connected to the field device via a communication link, wherein a control unit identifier and an existing access key are stored in the control unit, wherein the field device checks the access authorization of the control unit by at least indirect evaluation of the existing access key and the existing access key of the control unit, and wherein, when the access authorization is present, the control unit agrees on a new access key with the field device that stores as a new existing access key, the method comprising:
providing a key database on a database server and the key database for a plurality of field devices contains at least the field device identifier of the respective field device, the existing access key of the respective field device and the identifier of at least one of a user authorized to access and a control unit authorized to access the respective field device; generating, by the database server, a key data set for the at least one of the user authorized to access and the control unit authorized to access from the key database, wherein the key data set for the field devices, to which the at least one of the access-authorized user and the access-authorized control unit has access authorization, includes the field device identifier and the existing access key of the respective field device; and transferring the key data set to the control unit of the at least one of the access-authorized user and the access-authorized control unit, causing the control unit of the at least one of the access-authorized user and the access-authorized control unit to have the existing access keys of the field devices for which an access authorization exists; wherein the original entry time of the existing access key is also noted in at least one of the key database, the key data set generated from the key database, and the key data set of the control unit for the existing access keys; wherein, in a synchronization step, the key database and the key data set of at least one control unit are compared with regard to the entry times of corresponding existing access keys, and, if the entry times differ, the newest existing access key is subsequently entered there with an entry time, where only the older existing access key is present, causing the key database and the key data set of the control unit to have matching existing access keys for the respective field device; wherein a new access key for the field device is provided to the key database of the database server, and the new access key is stored by the key database for the field device as a new existing access key, and at least the last valid existing access key for the field device remains stored in the key database as an old existing access key; wherein, when the key data set is generated, the existing access key and at least the last valid existing access key for the field device are included in the key data set; wherein, in the synchronization step, when the latest existing access key is subsequently entered in the control unit, at least the previously valid older existing access key is retained; wherein the new access key is stored in the key database for the field device as a new existing access key and is provided with a synchronization flag; wherein the synchronization flag indicates whether the new existing access key is stored on the field device or is not stored on the field device; and wherein the synchronization flag indicates that the existing access key is not stored on the field device, wherein the synchronization flag is included in the key data set when the key data set is generated, and wherein the synchronization flag is adjusted in the synchronization step, but the synchronization flag is only changed from “existing access key not stored on the field device” to “existing access key stored on the field device”.
2 . The method according to claim 1 , wherein the key data set is encrypted before transmission to the control unit of the at least one of the access-authorized user and the access-authorized control unit, and the encrypted key data set is decrypted on the control unit before use.
3 . The method according to claim 1 , wherein a new access key is provided to the field unit by the control unit connected to the field unit via the communication link, and the new access key is stored by the field unit as a new existing access key;
wherein the control unit stores the new access key as a new existing access key in the key data set; and wherein the control unit either establishes a link to the key database of the database server and initiates the synchronization step or requests the user of the control unit to establish a link to the key database in order to be able to carry out the synchronization step.
4 . The method according to claim 1 , wherein the control unit is connected to the field device to which it has access authorization;
wherein the control unit has a key data set with the existing access key and the previously valid existing access key for the field device; wherein the control unit uses the previously valid existing access key to obtain access authorization to the field device and transmits the existing access key as a new access key to the field device when the access authorization is available.
5 . The method according to claim 1 , wherein the control unit is connected to the field device to which it has access authorization;
wherein the control unit has a key data set with the existing access key and the previously valid existing access key for the field device; wherein the control unit first uses the existing access key to obtain access authorization to the field device and, if access authorization is denied, uses the previously valid existing access key.
6 . The method according to claim 1 , wherein the control unit is connected to the field device, the control unit evaluates the synchronization flag of the existing access key and in that case;
wherein the synchronization flag indicates “existing access key not stored on the field device”, the control unit uses the previously valid existing access key to obtain access authorization to the field device and otherwise uses the existing access key.
7 . The method according to claim 6 , wherein the control unit is connected to the field device to which it has access authorization, and the control unit changes the synchronization flag of the transmitted new existing access key to “existing access key stored on field device” in the key data set after transmission of the new existing access key to the field device.
8 . The method according to claim 1 , wherein the synchronization step is carried out automatically after a control unit connects to the key database of the database server.Join the waitlist — get patent alerts
Track US12512982B2 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.